VYPR

Vendor CVEs

Fortinet

All CVEs

1,159 total · sorted by risk
  • CVE-2008-5531Dec 12, 2008
    risk 0.00cvss —epss 0.03

    Fortinet Antivirus 3.113.0.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension,…

  • CVE-2008-0779Feb 14, 2008
    risk 0.00cvss —epss 0.00

    The fortimon.sys device driver in Fortinet FortiClient Host Security 3.0 MR5 Patch 3 and earlier does not properly initialize its DeviceExtension, which allows local users to access kernel memory and execute arbitrary code via a crafted request.

  • CVE-2006-3222Jun 24, 2006
    risk 0.00cvss —epss 0.02

    The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode.

  • CVE-2006-1966Apr 21, 2006
    risk 0.00cvss —epss 0.02

    An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a "small synflood" to the SMTP port (TCP port 25), as demonstrated by a 10-microsecond wait between sending packets. NOTE: this issue has been disputed in followup…

  • CVE-2005-3057Dec 31, 2005
    risk 0.00cvss —epss 0.03

    The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as…

  • CVE-2005-4570Dec 29, 2005
    risk 0.00cvss —epss 0.02

    The Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS 2.50, 2.80 and 3.0, FortiClient 2.0,; and FortiManager 2.80 and 3.0 allow remote attackers to cause a denial of service (termination of a process that is automatically restarted) via IKE packets with…

  • CVE-2005-3400Nov 1, 2005
    risk 0.00cvss —epss 0.01

    Multiple interpretation error in Fortinet 2.48.0.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still…

  • CVE-2005-3221Oct 14, 2005
    risk 0.00cvss —epss 0.02

    Multiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar…

  • CVE-2005-1837Jun 1, 2005
    risk 0.00cvss —epss 0.01

    Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges.

Page 24 of 24